Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Tag

#Credential Theft

7 articles covering Credential Theft across campaign analysis, detection engineering, and defender tradecraft.

Coverage

7 entries

Field Analysis

Blue TeamTradecraft LabsJun 12, 202610 min read

The Recruiting Repo Is the Payload

A fake recruiter asking a candidate to review an MVP repo shows why unsolicited source code is not a document. It is an executable threat surface with access to developer secrets.

Read more:Reddit r/cybersecurityMicrosoft Security Blog

By PhishPond Desk

  • #Developer Security
  • #Fake Recruiters
  • #Supply Chain

Field Analysis

Blue TeamCampaign AnalysisMay 31, 20266 min read

FortiClient EMS Abuse Shows Why Management Planes Are Credential-Theft Surface

Recent exploitation of CVE-2026-35616 turned FortiClient EMS into a malware delivery channel, pushing an EKZ credential stealer through trusted endpoint management paths.

Read more:Arctic WolfArctic Wolf

By PhishPond Desk

  • #Campaign Analysis
  • #Credential Theft
  • #Endpoint Management

Field Analysis

Blue TeamCampaign AnalysisMay 6, 20268 min read

Compliance Lures Are Becoming Multi-Stage AiTM Token Traps

Recent code-of-conduct phishing campaigns show how attackers blend HR pressure, PDF staging, CAPTCHA gates, and AiTM flows to steal session tokens.

Read more:Microsoft Security BlogMicrosoft Security Blog

By PhishPond Desk

  • #AiTM
  • #Credential Theft
  • #CAPTCHA

Field Analysis

Blue TeamDetection & ValidationMay 6, 20268 min read

Unmanaged OAuth Grants Are the SaaS Back Door Hiding in Plain Sight

Persistent OAuth grants let third-party apps keep operating after the original login, password reset, or employee lifecycle event has faded from view.

Read more:The Hacker NewsMicrosoft Learn

By PhishPond Desk

  • #OAuth
  • #SaaS Security
  • #Credential Theft

Field Analysis

Red TeamInfrastructure IntelligenceMay 1, 20269 min read

Bluekit Shows Phishing Kits Are Becoming Campaign Workbenches

A newly reported kit packages templates, domain setup, anti-analysis controls, session monitoring, and AI-assisted drafting into one operator console.

Read more:BleepingComputerVaronis

By PhishPond Desk

  • #Phishing Kits
  • #AI
  • #Credential Theft

Field Analysis

Blue TeamResearch ReportsApr 30, 20268 min read

Q1 Email Threat Data Points Defenders Toward Links, QR Codes, and BEC

Microsoft's Q1 2026 email threat review shows link-based phishing dominance, QR code growth, CAPTCHA-gated flows, and persistent business email compromise pressure.

Read more:Microsoft Security Blog

By PhishPond Desk

  • #Research Reports
  • #QR Phishing
  • #BEC

Field Analysis

Red TeamCampaign AnalysisApr 23, 202611 min read

Developer Tooling Compromise Turns Trusted Packages Into Phishing Surface

Recent package compromises show how developer trust can be abused to harvest credentials and seed downstream phishing risk.

Read more:BleepingComputerCISA

By PhishPond Desk

  • #Supply Chain
  • #Developer Security
  • #Credential Theft

Browse Other Tags

#Detection Engineering#OAuth#Identity#Supply Chain#AiTM#Campaign Analysis#Infrastructure Intelligence#MFA Bypass#SaaS Security#Tradecraft Labs#ClickFix#Developer Security